First published: Mon May 10 2010(Updated: )
** DISPUTED ** SQL injection vulnerability in index.php in TYPO3 4.0 allows remote attackers to execute arbitrary SQL commands via the showUid parameter. NOTE: the TYPO3 Security Team disputes this report, stating that "there is no such vulnerability... The showUid parameter is generally used in third-party TYPO3 extensions - not in TYPO3 Core."
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Typo3 Typo3 | =4.0 | |
TYPO3 | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-4855 is disputed by the TYPO3 Security Team, claiming no actual vulnerability exists.
Since CVE-2009-4855 is disputed and not officially recognized as a vulnerability, no specific fix is provided.
CVE-2009-4855 was reported to allow remote SQL command execution, although this claim is contested.
TYPO3 version 4.0 is involved in this CVE report but the vulnerability is disputed.
The vulnerability of CVE-2009-4855 was reported by external sources, but it has been disputed by the TYPO3 Security Team.